Show filters
170 Total Results
Displaying 141-150 of 170
Sort by:
Attacker Value
Unknown
CVE-2017-6403
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.
0
Attacker Value
Unknown
CVE-2017-6408
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.
0
Attacker Value
Unknown
CVE-2017-6409
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access.
0
Attacker Value
Unknown
CVE-2016-7399
Disclosure Date: January 04, 2017 (last updated November 25, 2024)
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.
0
Attacker Value
Unknown
CVE-2015-8960
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.
0
Attacker Value
Unknown
CVE-2015-6551
Disclosure Date: May 07, 2016 (last updated November 25, 2024)
Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS for administration-console traffic to the NBU server, which allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets.
0
Attacker Value
Unknown
CVE-2015-6550
Disclosure Date: May 07, 2016 (last updated November 25, 2024)
bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary commands via crafted input.
0
Attacker Value
Unknown
CVE-2015-6552
Disclosure Date: May 07, 2016 (last updated November 25, 2024)
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to make arbitrary RPC calls via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-6549
Disclosure Date: October 06, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in an application console in the server in Symantec NetBackup OpsCenter before 7.7.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-1483
Disclosure Date: March 06, 2015 (last updated October 05, 2023)
Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vectors.
0